PM-26 Complaint Management. Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes: Mechanisms that are easy to use and readily accessible
Complaint Management. Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy practices that includes: Mechanisms that are eas.
system holds itEvidence a system already holds
- Tracking records showing each complaint logged, acknowledged and responded to within the defined time periods · HR system / LMS
periodic reviewEvidence produced at each review
- The intake mechanisms offered and evidence they are easy to use and readily accessible · Document repository
- The complaint response records themselves, showing what was decided and communicated · Document repository
- Review records showing complaints are analysed for systemic issues · Document repository
governing documentDocuments that govern the control
- The documented complaint management process for security and privacy complaints, concerns and questions · Policy repository / GRC workspace
First move
Common gaps auditors find
- Intake exists only as a general contact form, so complaints are not identified as such and are never tracked
- Response time periods undefined, so nothing is late and nothing is escalated
- Complaints closed individually with no trend analysis, so a repeated root cause is never addressed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research. Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training, and research; Limit or · PM-27 Privacy Reporting. Develop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy mandates; and [organization-defined] and other personnel with responsibility for monitoring privacy program compliance; and Review and update